CVE-2023-30177Cross-site Scripting in CMS

Severity
6.1MEDIUMNVD
EPSS
0.1%
top 68.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 25

Description

CraftCMS 3.7.59 is vulnerable Cross Site Scripting (XSS). An attacker can inject javascript code into Volume Name.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

Packagistcraftcms/cms< 3.7.68
NVDcraftcms/craft_cms3.7.59

Patches

🔴Vulnerability Details

3
OSV
Cross Site Scripting in CraftCMS2023-04-25
GHSA
Cross Site Scripting in CraftCMS2023-04-25
CVEList
CVE-2023-30177: CraftCMS 32023-04-25
CVE-2023-30177 — Cross-site Scripting in Craftcms CMS | cvebase